Back to skill

Security audit

抖音热点上升榜

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Douyin analytics purpose, but it automatically saves full search, post, and comment results to local plaintext logs without opt-in or retention controls.

Review before installing if you will collect large comment or profile datasets. Use it only when you are comfortable sending Douyin query data and URLs to guaikei.com with your API token, and regularly inspect or delete the generated logs directory because full results are saved locally by default.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/douyin/comment-cli.js:151
Finding

Automatic Plaintext Retention of Complete API Results

Content
View full analysis
Remediation
View remediation
` or `--save` so data is written only with informed user consent. 3. If persistence is enabled, create files with owner-only permissions: ```js await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, }); ``` 4. Minimize stored data by excluding unnecessary profile identifiers, full comments, runtime metadata, and original request values. 5. Add optional redaction or pseudonymization for usernames, user IDs, and profile URLs. 6. Provide configurable retention and automatic deletion, such as deleting files after a defined number of hours or days. 7. Add a cleanup command and document how to securely remove stored results. 8. Ensure the `logs/` directory is excluded from source control, package publication, crash reports, workspace synchronization, and build artifacts. 9. Clearly disclose the default storage behavior and retention policy in `SKILL.md`, not only in supplementary documentation. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
src/utils/request.js:19
Finding

Unbounded Buffering of Third-Party HTTP Responses

Content
View full analysis
{ res.setEncoding("utf-8"); let body = ""; res.on("data", (chunk) => (body += chunk)); res.on("end", () => { ``` ### Technical Analysis The HTTP client appends every response chunk to the `body` string and does not enforce a maximum response size. The response is retained entirely in memory before JSON parsing. The API is operated by a third party, and supported requests can ask for up to 10,000 records. A malfunctioning, compromised, or unexpectedly verbose API endpoint can therefore return a response large enough to consume excessive Node.js heap memory. The existing 20-second timeout limits response duration but does not impose a byte limit. A sufficiently fast server can deliver a very large body within that timeout. The code also does not validate the `Content-Length` header or stop reading after a safe threshold. ### Attack Path 1. The user invokes any CLI operation that calls `www.guaikei.com`. 2. The third-party endpoint is compromised, malfunctions, or returns an unexpectedly large result. 3. The server sends a very large response before the configured timeout expires. 4. Every chunk is appended to the in-memory `body` string. 5. Memory usage continues growing because no maximum byte count is enforced. 6. The Node.js process experiences severe garbage-collection pressure, reaches its heap limit, crashes, or is terminated by the host. 7. If the Skill runs inside a shared agent process or constrained container, the surrounding agent operation may also be disrupted. ### Impact Assessment The issue primarily affects availability. It does not directly provide filesystem access, code execution, or privilege escalation. Possible consequences ...[truncated 428 chars]
Remediation
View remediation
{ receivedBytes += Buffer.byteLength(chunk, "utf8"); if (receivedBytes > MAX_RESPONSE_BYTES) { req.destroy( new Error(`Response exceeds ${MAX_RESPONSE_BYTES} bytes`), ); return; } body += chunk; }); ``` 4. Ensure oversized-response errors are marked non-retryable so retry logic does not repeatedly download the same payload. 5. For large result sets, use incremental JSON parsing or paginated API retrieval rather than buffering the entire response. 6. Apply a lower configurable maximum `limit` where operationally feasible. 7. Add tests covering oversized `Content-Length`, chunked oversized responses, malformed JSON, and responses delivered just below the timeout. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向抖音内容洞察的业务技能,核心能力应涉及网络请求、抖音资源访问、数据抓取/查询、趋势分析与结果整理。但提供的代码片段仅是通用 CLI 参数解析器,没有出现任何与抖音、热点、搜索、博主作品、评论、数据分析或趋势视图相关的实现。该代码的主功能与声明用途 materially different,属于明显不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/changelog.md (reported line 72)May include surrounding context.

md
- 技能重命名为“douyin-search-keyword”。
- 在SKILL.md中添加了openclaw元数据、使用帮助、许可证、标签和示例,以实现更好的集成与文档化。
- 移除了两个本地文件(.env 和 scripts/last-search.json),以优化代码结构并提升安全性。
- 文档现已更加简洁且以用户为中心,重点在于提供清晰的使用说明和数据字段解释。
- 突出技能特性、合规要点及技术流程。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON schema includes user-facing natural-language fields such as title and description entirely in Chinese, and it does not provide any opt-in, alternative locale, or indication that the skill is region-specific. That can violate language/locale policy because it effectively forces a specific language on consumers of the skill metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout, such as the title on L004 and property descriptions across the schema. Because the file provides no opt-in, alternative locale, or documentation that the skill is intentionally China/Chinese-specific, it creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that collected Douyin data is automatically exported to local JSON logs, but it does not clearly warn that search results, public profile data, and especially comment data may still contain personal or sensitive information and may persist on disk longer than intended. In a scraping/analytics skill focused on bulk collection and comment analysis, silent local retention increases the risk of unauthorized access, over-retention, accidental sharing, and downstream misuse of scraped data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill documentation is presented only in Chinese, including headings, parameter descriptions, and examples, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only audience for compliance or regional reasons. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs an outbound API call to create a Douyin comment task and transmits user-provided URL data along with a token, but there is no confirmation prompt, user-facing log, or explicit warning in the file. Because this is a code file and the operation sends potentially sensitive user/system data over the network, it meets the missing-warning criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This request sends the video URL and token to a remote endpoint to query comment task results, yet the file contains no visible confirmation, print/log notice, or inline warning about the transmission. Under the code-file criteria, network calls that transmit user or system data should have some form of user disclosure unless already clearly warned elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The CLI persists fetched comment results to a local JSON file automatically, and those results may contain user-generated content and interaction metadata that can be sensitive or regulated depending on the environment. Because this happens without explicit opt-in, warning, or controls over destination/retention, it creates a privacy and data-handling risk through unintended local storage and later disclosure to other users, processes, backups, or logs on the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file contains multiple natural-language strings in Chinese for status, errors, and success messages, which effectively forces a specific language for users. Under the policy, language-specific behavior should offer user opt-in or be clearly justified as locale-specific, neither of which is present in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI writes the fetched Douyin results to a local JSON file automatically after successful execution, without explicit user consent, opt-out, or warning in this code path. Because the fetched data can include creator metadata and potentially comment/interaction-derived content in the broader skill context, this creates a privacy and data-handling risk: sensitive or regulated data may persist on disk longer than intended, be picked up by backups, or be exposed to other local users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists full search results to a local file automatically, without an explicit opt-in, path disclosure, or data-retention control. In this skill’s context, results can include scraped public content metadata and potentially comment/interaction data; silent logging increases privacy and data-handling risk, especially on shared machines, CI runners, or multi-user environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing status and error messages in Chinese, such as the validation errors on L07 and L11, without any apparent user opt-in or locale selection. Under the policy, forcing a specific language is a natural-language policy violation unless the skill offers a language choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The success and failure messages on L36-L38 are also hardcoded in Chinese, which continues the same language-forcing behavior for runtime output. Because no alternative language handling or documented regional limitation is present in this file, this appears to violate the language/locale policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs outbound HTTPS requests and includes both serialized request data and a TOKEN header, which may transmit user or system data to an external service. Within this file, there is no confirmation prompt, user-facing notice, or warning comment/docstring describing that network transmission occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits all user-facing status and warning messages exclusively in Chinese, including error, info, and success text. For a general-purpose skill utility, hard-coding a single language without user selection or documented locale scope is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file uses Chinese exclusively in docstrings, validation errors, and formatted output messages, which imposes a specific language/locale on users. Under the policy, language constraints should either offer user opt-in/choice or be explicitly justified as region-specific; neither is present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description forces a specific language for understanding and use of the skill, but does not state that the skill is intended only for Chinese-speaking users or offer an alternative language option. This can violate language/locale policy when users are not given opt-in or a documented justification for the language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill guidance, warnings, and usage instructions are entirely in Chinese, which effectively imposes a language requirement on all users. The file does not explicitly offer language selection or document the restriction as a justified locale-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title and description fields force a specific language/locale in natural-language metadata. The policy allows locale constraints when documented and justified or when users are given a choice, but this schema provides neither, so it may violate language-choice expectations for broader users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON schema contains user-facing natural-language strings such as the title and descriptions exclusively in Chinese. Because the file does not document that the skill is region-specific or offer a language choice, it may violate a language/locale policy requiring opt-in or justification for a forced locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The schema title and field descriptions are written entirely in Chinese, which imposes a specific language/locale in the skill's natural-language interface metadata. There is no indication of user opt-in, multilingual support, or documented region-specific justification, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON schema uses Chinese-only natural-language titles and descriptions throughout the file, which can impose a specific language/locale on downstream users or tooling. The file does not indicate that the schema is intentionally region-specific or provide any opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The title and field descriptions are written entirely in Chinese, which imposes a specific language on users or downstream tooling without any visible opt-in or statement that the skill is intended only for a Chinese-speaking or region-specific context. Under the policy, locale or language constraints should either be optional for users or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:16